{"schema_version":1,"title":"Most vulnerable technologies in April 2026","summary":"In April 2026, Junglewise Threat Intelligence recorded 3,561 new vulnerabilities: 379 critical, 1,331 high and 35 exploited in the wild. The most vulnerable technology was Linux Kernel, with 300 vulnerabilities (20 critical, 2 exploited in the wild), followed by Openclaw (260) and Microsoft Windows (108).","url":"https://junglewise.ai/threats/monthly/2026-04","json_url":"https://junglewise.ai/threats/monthly/2026-04.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/monthly/2026-04","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","method":"Technologies are ranked by 10 points per vulnerability exploited in the wild, 5 per critical, 2 per high and 1 per vulnerability, over vulnerabilities published in the period (UTC). A vulnerability counts for every technology it affects.","kind":"month","period":{"end":"2026-04-30","start":"2026-04-01"},"totals":{"high":1331,"critical":379,"exploited":35,"technologies":2159,"vulnerabilities":3561},"notable":[{"cve":"CVE-2025-32975","cvss":10,"epss":0.465,"slug":"cve-2025-32975-quest-kace-systems-management-appliance-authentication-bypass-in","title":"Quest KACE Systems Management Appliance authentication bypass in SSO","severity":"critical","exploited":true,"published_at":"2026-04-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-32975-quest-kace-systems-management-appliance-authentication-bypass-in"},{"cve":"CVE-2024-57726","cvss":9.9,"epss":0.4596,"slug":"cve-2024-57726-simplehelp-privilege-escalation-via-missing-authorization-in-api","title":"SimpleHelp privilege escalation via missing authorization in API key creation","severity":"critical","exploited":true,"published_at":"2026-04-24T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-57726-simplehelp-privilege-escalation-via-missing-authorization-in-api"},{"cve":"CVE-2026-35616","cvss":9.8,"epss":0.8894,"slug":"cve-2026-35616-fortinet-forticlientems-improper-access-control-in-api","title":"Fortinet FortiClientEMS improper access control in API","severity":"critical","exploited":true,"published_at":"2026-04-04T01:16:39.72+00:00","url":"https://junglewise.ai/threats/cve-2026-35616-fortinet-forticlientems-improper-access-control-in-api"},{"cve":"CVE-2024-7399","cvss":9.8,"epss":0.844,"slug":"cve-2024-7399-samsung-magicinfo-9-server-path-traversal","title":"Samsung MagicINFO 9 Server path traversal","severity":"critical","exploited":true,"published_at":"2026-04-24T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-7399-samsung-magicinfo-9-server-path-traversal"},{"cve":"CVE-2026-41940","cvss":9.8,"epss":0.7424,"slug":"cve-2026-41940-webpros-cpanel-whm-authentication-bypass-in-login-flow","title":"WebPros cPanel & WHM authentication bypass in login flow","severity":"critical","exploited":true,"published_at":"2026-04-30T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-41940-webpros-cpanel-whm-authentication-bypass-in-login-flow"},{"cve":"CVE-2026-1340","cvss":9.8,"epss":0.6573,"slug":"cve-2026-1340-ivanti-endpoint-manager-mobile-code-injection","title":"Ivanti Endpoint Manager Mobile code injection","severity":"critical","exploited":true,"published_at":"2026-04-08T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-1340-ivanti-endpoint-manager-mobile-code-injection"},{"cve":"CVE-2026-21643","cvss":9.8,"epss":0.6252,"slug":"cve-2026-21643-fortinet-forticlient-ems-sql-injection","title":"Fortinet FortiClient EMS SQL injection","severity":"critical","exploited":true,"published_at":"2026-04-13T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-21643-fortinet-forticlient-ems-sql-injection"},{"cve":"CVE-2026-39808","cvss":9.8,"epss":0.4867,"slug":"cve-2026-39808-fortinet-fortisandbox-os-command-injection-in-api-endpoint","title":"Fortinet FortiSandbox OS command injection in API endpoint","severity":"critical","exploited":true,"published_at":"2026-04-14T16:16:44.86+00:00","url":"https://junglewise.ai/threats/cve-2026-39808-fortinet-fortisandbox-os-command-injection-in-api-endpoint"},{"cve":"CVE-2026-39987","cvss":9.8,"epss":0.3787,"slug":"cve-2026-39987-marimo-pre-auth-remote-code-execution-via-terminal-websocket","title":"Marimo: Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass","severity":"critical","exploited":true,"published_at":"2026-04-08T21:50:58+00:00","url":"https://junglewise.ai/threats/cve-2026-39987-marimo-pre-auth-remote-code-execution-via-terminal-websocket"},{"cve":"CVE-2026-33824","cvss":9.8,"epss":0.0162,"slug":"cve-2026-33824-microsoft-windows-double-free-in-ike-extension","title":"Microsoft Windows double free in IKE Extension","severity":"critical","exploited":true,"published_at":"2026-04-14T18:17:34.767+00:00","url":"https://junglewise.ai/threats/cve-2026-33824-microsoft-windows-double-free-in-ike-extension"}],"vendors":[{"hub":true,"high":147,"name":"Linux","rank":1,"slug":"linux","critical":20,"exploited":2,"vulnerabilities":300,"url":"https://junglewise.ai/threats/vendors/linux"},{"hub":true,"high":88,"name":"Microsoft","rank":2,"slug":"microsoft","critical":21,"exploited":11,"vulnerabilities":159,"url":"https://junglewise.ai/threats/vendors/microsoft"},{"hub":true,"high":66,"name":"Npm","rank":3,"slug":"npm","critical":21,"exploited":0,"vulnerabilities":215,"url":"https://junglewise.ai/threats/vendors/npm"},{"hub":true,"high":63,"name":"Go","rank":4,"slug":"go","critical":16,"exploited":0,"vulnerabilities":145,"url":"https://junglewise.ai/threats/vendors/go"},{"hub":true,"high":32,"name":"Openclaw","rank":5,"slug":"openclaw","critical":4,"exploited":0,"vulnerabilities":260,"url":"https://junglewise.ai/threats/vendors/openclaw"},{"hub":true,"high":79,"name":"Google","rank":6,"slug":"google","critical":7,"exploited":1,"vulnerabilities":129,"url":"https://junglewise.ai/threats/vendors/google"},{"hub":true,"high":36,"name":"Pip","rank":7,"slug":"pip","critical":16,"exploited":0,"vulnerabilities":106,"url":"https://junglewise.ai/threats/vendors/pip"},{"hub":true,"high":62,"name":"Apple","rank":8,"slug":"apple","critical":4,"exploited":1,"vulnerabilities":104,"url":"https://junglewise.ai/threats/vendors/apple"},{"hub":true,"high":41,"name":"Red Hat","rank":9,"slug":"red-hat","critical":11,"exploited":0,"vulnerabilities":73,"url":"https://junglewise.ai/threats/vendors/red-hat"},{"hub":true,"high":31,"name":"Composer","rank":10,"slug":"composer","critical":8,"exploited":0,"vulnerabilities":68,"url":"https://junglewise.ai/threats/vendors/composer"}],"generated_at":"2026-09-26T10:07:00.179841+00:00","technologies":[{"hub":true,"top":[{"cve":"CVE-2026-5281","cvss":8.8,"epss":0.0504,"slug":"cve-2026-5281-google-chrome-use-after-free-in-dawn","title":"Google Chrome use after free in Dawn","severity":"critical","exploited":true,"published_at":"2026-04-01T05:16:01.44+00:00","url":"https://junglewise.ai/threats/cve-2026-5281-google-chrome-use-after-free-in-dawn"},{"cve":"CVE-2026-31431","cvss":7.8,"epss":0.0257,"slug":"cve-2026-31431-linux-kernel-crypto-algif-aead-improper-memory-handling","title":"Linux Kernel crypto algif_aead improper memory handling","severity":"critical","exploited":true,"published_at":"2026-04-22T09:16:21.27+00:00","url":"https://junglewise.ai/threats/cve-2026-31431-linux-kernel-crypto-algif-aead-improper-memory-handling"},{"cve":"CVE-2026-31669","cvss":9.8,"epss":0.004,"slug":"cve-2026-31669-linux-kernel-slab-use-after-free-in-mptcp-ipv6-subflow","title":"Linux Kernel slab-use-after-free in MPTCP IPv6 subflow","severity":"critical","exploited":false,"published_at":"2026-04-24T15:16:46.663+00:00","url":"https://junglewise.ai/threats/cve-2026-31669-linux-kernel-slab-use-after-free-in-mptcp-ipv6-subflow"}],"high":147,"name":"Linux Kernel","rank":1,"slug":"kernel","score":714,"vendor":{"name":"Linux","slug":"linux"},"critical":20,"max_cvss":9.8,"max_epss":0.0504,"exploited":2,"vulnerabilities":300,"url":"https://junglewise.ai/threats/technologies/kernel"},{"hub":true,"top":[{"cve":"CVE-2026-41294","cvss":9.6,"epss":0.0019,"slug":"cve-2026-41294-openclaw-has-a-cwd-env-environment-variable-injection-which","title":"OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeover","severity":"critical","exploited":false,"published_at":"2026-04-01T00:02:42+00:00","url":"https://junglewise.ai/threats/cve-2026-41294-openclaw-has-a-cwd-env-environment-variable-injection-which"},{"cvss":9.3,"slug":"openclaw-authentication-bypass-in-feishu-webhook-and-card-action-af7876b6","title":"OpenClaw authentication bypass in Feishu webhook and card-action validation","severity":"critical","exploited":false,"published_at":"2026-04-17T22:32:47+00:00","url":"https://junglewise.ai/threats/openclaw-authentication-bypass-in-feishu-webhook-and-card-action-af7876b6"},{"cve":"CVE-2026-35663","cvss":8.8,"epss":0.0052,"slug":"cve-2026-35663-openclaw-privilege-escalation-in-gateway-backend-reconnect","title":"OpenClaw privilege escalation in gateway backend reconnect","severity":"critical","exploited":false,"published_at":"2026-04-10T17:17:08.047+00:00","url":"https://junglewise.ai/threats/cve-2026-35663-openclaw-privilege-escalation-in-gateway-backend-reconnect"}],"high":32,"name":"Openclaw","rank":2,"slug":"openclaw","score":344,"vendor":{"name":"Openclaw","slug":"openclaw"},"critical":4,"max_cvss":9.6,"max_epss":0.0109,"exploited":0,"vulnerabilities":260,"url":"https://junglewise.ai/threats/technologies/openclaw"},{"hub":true,"top":[{"cve":"CVE-2026-5281","cvss":8.8,"epss":0.0504,"slug":"cve-2026-5281-google-chrome-use-after-free-in-dawn","title":"Google Chrome use after free in Dawn","severity":"critical","exploited":true,"published_at":"2026-04-01T05:16:01.44+00:00","url":"https://junglewise.ai/threats/cve-2026-5281-google-chrome-use-after-free-in-dawn"},{"cve":"CVE-2024-1708","cvss":8.4,"epss":0.8527,"slug":"cve-2024-1708-connectwise-screenconnect-path-traversal","title":"ConnectWise ScreenConnect path traversal","severity":"critical","exploited":true,"published_at":"2026-04-28T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-1708-connectwise-screenconnect-path-traversal"},{"cve":"CVE-2023-36424","cvss":7.8,"epss":0.1092,"slug":"cve-2023-36424-microsoft-windows-privilege-escalation-in-common-log-file-system","title":"Microsoft Windows privilege escalation in Common Log File System Driver","severity":"critical","exploited":true,"published_at":"2026-04-13T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-36424-microsoft-windows-privilege-escalation-in-common-log-file-system"}],"high":62,"name":"Microsoft Windows","rank":3,"slug":"windows-","score":322,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":8,"max_cvss":9.8,"max_epss":0.8527,"exploited":5,"vulnerabilities":108,"url":"https://junglewise.ai/threats/technologies/windows-"},{"hub":true,"top":[{"cve":"CVE-2026-5281","cvss":8.8,"epss":0.0504,"slug":"cve-2026-5281-google-chrome-use-after-free-in-dawn","title":"Google Chrome use after free in Dawn","severity":"critical","exploited":true,"published_at":"2026-04-01T05:16:01.44+00:00","url":"https://junglewise.ai/threats/cve-2026-5281-google-chrome-use-after-free-in-dawn"},{"cve":"CVE-2026-5902","cvss":9.8,"epss":0.0021,"slug":"cve-2026-5902-google-chrome-race-condition-in-media-component","title":"Google Chrome race condition in Media component","severity":"critical","exploited":false,"published_at":"2026-04-08T22:16:30.08+00:00","url":"https://junglewise.ai/threats/cve-2026-5902-google-chrome-race-condition-in-media-component"},{"cve":"CVE-2026-7333","cvss":9.6,"epss":0.0029,"slug":"cve-2026-7333-google-chrome-use-after-free-in-gpu","title":"Google Chrome use after free in GPU","severity":"critical","exploited":false,"published_at":"2026-04-28T23:16:20.843+00:00","url":"https://junglewise.ai/threats/cve-2026-7333-google-chrome-use-after-free-in-gpu"}],"high":76,"name":"Google Chrome","rank":4,"slug":"chrome","score":320,"vendor":{"name":"Google","slug":"google"},"critical":7,"max_cvss":9.8,"max_epss":0.0504,"exploited":1,"vulnerabilities":123,"url":"https://junglewise.ai/threats/technologies/chrome"},{"hub":true,"top":[{"cve":"CVE-2026-5281","cvss":8.8,"epss":0.0504,"slug":"cve-2026-5281-google-chrome-use-after-free-in-dawn","title":"Google Chrome use after free in Dawn","severity":"critical","exploited":true,"published_at":"2026-04-01T05:16:01.44+00:00","url":"https://junglewise.ai/threats/cve-2026-5281-google-chrome-use-after-free-in-dawn"},{"cve":"CVE-2026-5902","cvss":9.8,"epss":0.0021,"slug":"cve-2026-5902-google-chrome-race-condition-in-media-component","title":"Google Chrome race condition in Media component","severity":"critical","exploited":false,"published_at":"2026-04-08T22:16:30.08+00:00","url":"https://junglewise.ai/threats/cve-2026-5902-google-chrome-race-condition-in-media-component"},{"cve":"CVE-2026-7333","cvss":9.6,"epss":0.0029,"slug":"cve-2026-7333-google-chrome-use-after-free-in-gpu","title":"Google Chrome use after free in GPU","severity":"critical","exploited":false,"published_at":"2026-04-28T23:16:20.843+00:00","url":"https://junglewise.ai/threats/cve-2026-7333-google-chrome-use-after-free-in-gpu"}],"high":61,"name":"Apple macOS","rank":5,"slug":"macos-tahoe","score":254,"vendor":{"name":"Apple","slug":"apple"},"critical":4,"max_cvss":9.8,"max_epss":0.0504,"exploited":1,"vulnerabilities":102,"url":"https://junglewise.ai/threats/technologies/macos-tahoe"},{"hub":true,"top":[{"cve":"CVE-2026-31669","cvss":9.8,"epss":0.004,"slug":"cve-2026-31669-linux-kernel-slab-use-after-free-in-mptcp-ipv6-subflow","title":"Linux Kernel slab-use-after-free in MPTCP IPv6 subflow","severity":"critical","exploited":false,"published_at":"2026-04-24T15:16:46.663+00:00","url":"https://junglewise.ai/threats/cve-2026-31669-linux-kernel-slab-use-after-free-in-mptcp-ipv6-subflow"},{"cve":"CVE-2026-31649","cvss":9.8,"epss":0.0041,"slug":"cve-2026-31649-linux-kernel-stmmac-integer-underflow-in-jumbo-frm","title":"Linux Kernel stmmac integer underflow in jumbo_frm","severity":"critical","exploited":false,"published_at":"2026-04-24T15:16:44.33+00:00","url":"https://junglewise.ai/threats/cve-2026-31649-linux-kernel-stmmac-integer-underflow-in-jumbo-frm"},{"cve":"CVE-2026-31533","cvss":9.8,"epss":0.0026,"slug":"cve-2026-31533-linux-kernel-use-after-free-in-net-tls-encryption-error-path","title":"Linux Kernel use-after-free in net/tls encryption error path","severity":"critical","exploited":false,"published_at":"2026-04-23T18:16:26.857+00:00","url":"https://junglewise.ai/threats/cve-2026-31533-linux-kernel-use-after-free-in-net-tls-encryption-error-path"}],"high":19,"name":"Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","rank":6,"slug":"simatic-s7-1500-cpu-1518-4-pn-dp-mfp","score":114,"vendor":{"name":"Siemens","slug":"siemens"},"critical":6,"max_cvss":9.8,"max_epss":0.0048,"exploited":0,"vulnerabilities":46,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518-4-pn-dp-mfp"},{"hub":true,"top":[{"cve":"CVE-2025-50673","cvss":7.5,"epss":0.0041,"slug":"cve-2025-50673-d-link-di-8003-buffer-overflow-in-webgl-asp","title":"D-Link DI-8003 buffer overflow in /webgl.asp","severity":"high","exploited":false,"published_at":"2026-04-08T19:24:18.04+00:00","url":"https://junglewise.ai/threats/cve-2025-50673-d-link-di-8003-buffer-overflow-in-webgl-asp"},{"cve":"CVE-2025-50672","cvss":7.5,"epss":0.0041,"slug":"cve-2025-50672-d-link-di-8003-buffer-overflow-in-yyxz-dlink-asp","title":"D-Link DI-8003 buffer overflow in /yyxz_dlink.asp","severity":"high","exploited":false,"published_at":"2026-04-08T19:24:17.913+00:00","url":"https://junglewise.ai/threats/cve-2025-50672-d-link-di-8003-buffer-overflow-in-yyxz-dlink-asp"},{"cve":"CVE-2025-50671","cvss":7.5,"epss":0.0049,"slug":"cve-2025-50671-d-link-di-8003-buffer-overflow-in-xwgl-ref-asp","title":"D-Link DI-8003 buffer overflow in /xwgl_ref.asp","severity":"high","exploited":false,"published_at":"2026-04-08T19:24:17.803+00:00","url":"https://junglewise.ai/threats/cve-2025-50671-d-link-di-8003-buffer-overflow-in-xwgl-ref-asp"}],"high":27,"name":"Dlink Di-8003","rank":7,"slug":"di-8003","score":81,"vendor":{"name":"Dlink","slug":"dlink"},"critical":0,"max_cvss":7.5,"max_epss":0.0061,"exploited":0,"vulnerabilities":27,"url":"https://junglewise.ai/threats/technologies/di-8003"},{"hub":true,"top":[{"cve":"CVE-2025-50673","cvss":7.5,"epss":0.0041,"slug":"cve-2025-50673-d-link-di-8003-buffer-overflow-in-webgl-asp","title":"D-Link DI-8003 buffer overflow in /webgl.asp","severity":"high","exploited":false,"published_at":"2026-04-08T19:24:18.04+00:00","url":"https://junglewise.ai/threats/cve-2025-50673-d-link-di-8003-buffer-overflow-in-webgl-asp"},{"cve":"CVE-2025-50672","cvss":7.5,"epss":0.0041,"slug":"cve-2025-50672-d-link-di-8003-buffer-overflow-in-yyxz-dlink-asp","title":"D-Link DI-8003 buffer overflow in /yyxz_dlink.asp","severity":"high","exploited":false,"published_at":"2026-04-08T19:24:17.913+00:00","url":"https://junglewise.ai/threats/cve-2025-50672-d-link-di-8003-buffer-overflow-in-yyxz-dlink-asp"},{"cve":"CVE-2025-50671","cvss":7.5,"epss":0.0049,"slug":"cve-2025-50671-d-link-di-8003-buffer-overflow-in-xwgl-ref-asp","title":"D-Link DI-8003 buffer overflow in /xwgl_ref.asp","severity":"high","exploited":false,"published_at":"2026-04-08T19:24:17.803+00:00","url":"https://junglewise.ai/threats/cve-2025-50671-d-link-di-8003-buffer-overflow-in-xwgl-ref-asp"}],"high":27,"name":"Dlink Di-8003 Firmware","rank":8,"slug":"di-8003-firmware","score":81,"vendor":{"name":"Dlink","slug":"dlink"},"critical":0,"max_cvss":7.5,"max_epss":0.0061,"exploited":0,"vulnerabilities":27,"url":"https://junglewise.ai/threats/technologies/di-8003-firmware"},{"hub":true,"top":[{"cve":"CVE-2026-33698","cvss":9.8,"slug":"cve-2026-33698-chamilo-lms-unauthenticated-rce-in-main-install-directory","title":"Chamilo LMS unauthenticated RCE in main/install directory","severity":"critical","exploited":false,"published_at":"2026-04-10T19:16:23.033+00:00","url":"https://junglewise.ai/threats/cve-2026-33698-chamilo-lms-unauthenticated-rce-in-main-install-directory"},{"cve":"CVE-2026-33707","cvss":9.4,"slug":"cve-2026-33707-chamilo-lms-weak-password-recovery-mechanism-in-login-lib-php","title":"Chamilo LMS weak password recovery mechanism in login.lib.php","severity":"critical","exploited":false,"published_at":"2026-04-10T19:16:23.95+00:00","url":"https://junglewise.ai/threats/cve-2026-33707-chamilo-lms-weak-password-recovery-mechanism-in-login-lib-php"},{"cve":"CVE-2026-32892","cvss":9.1,"slug":"cve-2026-32892-chamilo-lms-os-command-injection-in-file-move-function","title":"Chamilo LMS OS command injection in file move function","severity":"critical","exploited":false,"published_at":"2026-04-10T18:16:41.797+00:00","url":"https://junglewise.ai/threats/cve-2026-32892-chamilo-lms-os-command-injection-in-file-move-function"}],"high":17,"name":"Chamilo Lms","rank":9,"slug":"chamilo-lms","score":80,"vendor":{"name":"Chamilo","slug":"chamilo"},"critical":3,"max_cvss":9.8,"max_epss":0.0176,"exploited":0,"vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/chamilo-lms"},{"hub":true,"top":[{"cve":"CVE-2026-40933","cvss":9.9,"epss":0.0128,"slug":"cve-2026-40933-flowise-flowise-authenticated-rce-in-mcp-adapters","title":"Flowise Flowise authenticated RCE in MCP Adapters","severity":"critical","exploited":false,"published_at":"2026-04-16T21:18:17+00:00","url":"https://junglewise.ai/threats/cve-2026-40933-flowise-flowise-authenticated-rce-in-mcp-adapters"},{"cve":"CVE-2026-41264","cvss":9.8,"epss":0.0117,"slug":"cve-2026-41264-flowise-csv-agent-prompt-injection-remote-code-execution","title":"Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability","severity":"critical","exploited":false,"published_at":"2026-04-21T20:19:52+00:00","url":"https://junglewise.ai/threats/cve-2026-41264-flowise-csv-agent-prompt-injection-remote-code-execution"},{"cve":"CVE-2026-41265","cvss":9.8,"epss":0.0056,"slug":"cve-2026-41265-flowise-airtable-agent-code-injection-remote-code-execution","title":"Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability","severity":"critical","exploited":false,"published_at":"2026-04-18T00:46:04+00:00","url":"https://junglewise.ai/threats/cve-2026-41265-flowise-airtable-agent-code-injection-remote-code-execution"}],"high":15,"name":"Npm Flowise","rank":10,"slug":"flowise","score":76,"vendor":{"name":"Npm","slug":"npm"},"critical":4,"max_cvss":9.9,"max_epss":0.0205,"exploited":0,"vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/flowise"},{"hub":true,"top":[{"cve":"CVE-2026-6748","cvss":9.8,"epss":0.0039,"slug":"cve-2026-6748-mozilla-firefox-and-thunderbird-uninitialized-memory-in-web-codecs","title":"Mozilla Firefox and Thunderbird uninitialized memory in Web Codecs","severity":"critical","exploited":false,"published_at":"2026-04-21T13:16:20.91+00:00","url":"https://junglewise.ai/threats/cve-2026-6748-mozilla-firefox-and-thunderbird-uninitialized-memory-in-web-codecs"},{"cve":"CVE-2026-5735","cvss":9.8,"epss":0.0031,"slug":"cve-2026-5735-mozilla-firefox-and-thunderbird-memory-safety-bugs","title":"Mozilla Firefox and Thunderbird memory safety bugs","severity":"critical","exploited":false,"published_at":"2026-04-07T13:16:47.763+00:00","url":"https://junglewise.ai/threats/cve-2026-5735-mozilla-firefox-and-thunderbird-memory-safety-bugs"},{"cve":"CVE-2026-5734","cvss":9.8,"epss":0.0032,"slug":"cve-2026-5734-mozilla-firefox-and-thunderbird-memory-safety-bugs","title":"Mozilla Firefox and Thunderbird memory safety bugs","severity":"critical","exploited":false,"published_at":"2026-04-07T13:16:47.667+00:00","url":"https://junglewise.ai/threats/cve-2026-5734-mozilla-firefox-and-thunderbird-memory-safety-bugs"}],"high":17,"name":"Mozilla Firefox","rank":11,"slug":"firefox","score":75,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":4,"max_cvss":9.8,"max_epss":0.0058,"exploited":0,"vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/firefox"},{"hub":true,"top":[{"cve":"CVE-2026-6748","cvss":9.8,"epss":0.0039,"slug":"cve-2026-6748-mozilla-firefox-and-thunderbird-uninitialized-memory-in-web-codecs","title":"Mozilla Firefox and Thunderbird uninitialized memory in Web Codecs","severity":"critical","exploited":false,"published_at":"2026-04-21T13:16:20.91+00:00","url":"https://junglewise.ai/threats/cve-2026-6748-mozilla-firefox-and-thunderbird-uninitialized-memory-in-web-codecs"},{"cve":"CVE-2026-5735","cvss":9.8,"epss":0.0031,"slug":"cve-2026-5735-mozilla-firefox-and-thunderbird-memory-safety-bugs","title":"Mozilla Firefox and Thunderbird memory safety bugs","severity":"critical","exploited":false,"published_at":"2026-04-07T13:16:47.763+00:00","url":"https://junglewise.ai/threats/cve-2026-5735-mozilla-firefox-and-thunderbird-memory-safety-bugs"},{"cve":"CVE-2026-5734","cvss":9.8,"epss":0.0032,"slug":"cve-2026-5734-mozilla-firefox-and-thunderbird-memory-safety-bugs","title":"Mozilla Firefox and Thunderbird memory safety bugs","severity":"critical","exploited":false,"published_at":"2026-04-07T13:16:47.667+00:00","url":"https://junglewise.ai/threats/cve-2026-5734-mozilla-firefox-and-thunderbird-memory-safety-bugs"}],"high":17,"name":"Mozilla Thunderbird","rank":12,"slug":"thunderbird","score":75,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":4,"max_cvss":9.8,"max_epss":0.0058,"exploited":0,"vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/thunderbird"},{"hub":true,"top":[{"cve":"CVE-2026-39888","cvss":9.9,"epss":0.0048,"slug":"cve-2026-39888-praisonai-sandbox-escape-via-frame-traversal-in-execute-code","title":"PraisonAI sandbox escape via frame traversal in execute_code","severity":"critical","exploited":false,"published_at":"2026-04-08T21:17:00.99+00:00","url":"https://junglewise.ai/threats/cve-2026-39888-praisonai-sandbox-escape-via-frame-traversal-in-execute-code"},{"cve":"CVE-2026-39890","cvss":9.8,"epss":0.0081,"slug":"cve-2026-39890-mervinpraison-praisonai-rce-via-yaml-deserialization-in","title":"MervinPraison PraisonAI RCE via YAML deserialization in AgentService","severity":"critical","exploited":false,"published_at":"2026-04-08T21:17:01.267+00:00","url":"https://junglewise.ai/threats/cve-2026-39890-mervinpraison-praisonai-rce-via-yaml-deserialization-in"},{"cve":"CVE-2026-34935","cvss":9.8,"epss":0.0099,"slug":"cve-2026-34935-mervinpraison-praisonai-os-command-injection-in-mcphandler","title":"MervinPraison PraisonAI OS command injection in MCPHandler","severity":"critical","exploited":false,"published_at":"2026-04-03T23:17:05.693+00:00","url":"https://junglewise.ai/threats/cve-2026-34935-mervinpraison-praisonai-os-command-injection-in-mcphandler"}],"high":8,"name":"PraisonAI","rank":13,"slug":"praisonai","score":74,"vendor":{"name":"Praison","slug":"praison"},"critical":8,"max_cvss":9.9,"max_epss":0.0099,"exploited":0,"vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/praisonai"},{"hub":true,"top":[{"cve":"CVE-2026-33824","cvss":9.8,"epss":0.0162,"slug":"cve-2026-33824-microsoft-windows-double-free-in-ike-extension","title":"Microsoft Windows double free in IKE Extension","severity":"critical","exploited":true,"published_at":"2026-04-14T18:17:34.767+00:00","url":"https://junglewise.ai/threats/cve-2026-33824-microsoft-windows-double-free-in-ike-extension"},{"cve":"CVE-2026-32225","cvss":8.8,"epss":0.0091,"slug":"cve-2026-32225-microsoft-windows-shell-protection-mechanism-failure","title":"Microsoft Windows Shell protection mechanism failure","severity":"high","exploited":false,"published_at":"2026-04-14T18:17:30.85+00:00","url":"https://junglewise.ai/threats/cve-2026-32225-microsoft-windows-shell-protection-mechanism-failure"},{"cve":"CVE-2026-32221","cvss":8.4,"epss":0.0029,"slug":"cve-2026-32221-microsoft-graphics-component-heap-overflow-code-execution","title":"Microsoft Graphics Component heap overflow code execution","severity":"high","exploited":false,"published_at":"2026-04-14T18:17:30.087+00:00","url":"https://junglewise.ai/threats/cve-2026-32221-microsoft-graphics-component-heap-overflow-code-execution"}],"high":15,"name":"Microsoft Windows 11","rank":14,"slug":"windows-11","score":65,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":1,"max_cvss":9.8,"max_epss":0.0345,"exploited":1,"vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/windows-11"},{"hub":true,"top":[{"cve":"CVE-2026-31533","cvss":9.8,"epss":0.0026,"slug":"cve-2026-31533-linux-kernel-use-after-free-in-net-tls-encryption-error-path","title":"Linux Kernel use-after-free in net/tls encryption error path","severity":"critical","exploited":false,"published_at":"2026-04-23T18:16:26.857+00:00","url":"https://junglewise.ai/threats/cve-2026-31533-linux-kernel-use-after-free-in-net-tls-encryption-error-path"},{"cve":"CVE-2026-5450","cvss":9.8,"epss":0.0045,"slug":"cve-2026-5450-gnu-glibc-heap-buffer-overflow-in-scanf-mc-specifier","title":"GNU glibc heap buffer overflow in scanf %mc specifier","severity":"critical","exploited":false,"published_at":"2026-04-20T21:16:36.85+00:00","url":"https://junglewise.ai/threats/cve-2026-5450-gnu-glibc-heap-buffer-overflow-in-scanf-mc-specifier"},{"cve":"CVE-2026-31682","cvss":9.1,"epss":0.0042,"slug":"cve-2026-31682-linux-kernel-out-of-bounds-read-in-bridge-br-nd-send","title":"Linux Kernel out-of-bounds read in bridge br_nd_send","severity":"critical","exploited":false,"published_at":"2026-04-25T09:16:01.913+00:00","url":"https://junglewise.ai/threats/cve-2026-31682-linux-kernel-out-of-bounds-read-in-bridge-br-nd-send"}],"high":10,"name":"Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","rank":15,"slug":"simatic-s7-1500-cpu-1518f-4-pn-dp-mfp","score":64,"vendor":{"name":"Siemens","slug":"siemens"},"critical":3,"max_cvss":9.8,"max_epss":0.0048,"exploited":0,"vulnerabilities":29,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518f-4-pn-dp-mfp"},{"hub":true,"top":[{"cve":"CVE-2026-6748","cvss":9.8,"epss":0.0039,"slug":"cve-2026-6748-mozilla-firefox-and-thunderbird-uninitialized-memory-in-web-codecs","title":"Mozilla Firefox and Thunderbird uninitialized memory in Web Codecs","severity":"critical","exploited":false,"published_at":"2026-04-21T13:16:20.91+00:00","url":"https://junglewise.ai/threats/cve-2026-6748-mozilla-firefox-and-thunderbird-uninitialized-memory-in-web-codecs"},{"cve":"CVE-2026-5734","cvss":9.8,"epss":0.0032,"slug":"cve-2026-5734-mozilla-firefox-and-thunderbird-memory-safety-bugs","title":"Mozilla Firefox and Thunderbird memory safety bugs","severity":"critical","exploited":false,"published_at":"2026-04-07T13:16:47.667+00:00","url":"https://junglewise.ai/threats/cve-2026-5734-mozilla-firefox-and-thunderbird-memory-safety-bugs"},{"cve":"CVE-2026-5731","cvss":9.8,"epss":0.0034,"slug":"cve-2026-5731-mozilla-firefox-and-thunderbird-memory-safety-bugs","title":"Mozilla Firefox and Thunderbird memory safety bugs","severity":"critical","exploited":false,"published_at":"2026-04-07T13:16:47.347+00:00","url":"https://junglewise.ai/threats/cve-2026-5731-mozilla-firefox-and-thunderbird-memory-safety-bugs"}],"high":13,"name":"Mozilla Firefox ESR","rank":16,"slug":"firefox-esr","score":57,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":3,"max_cvss":9.8,"max_epss":0.0058,"exploited":0,"vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/firefox-esr"},{"hub":true,"top":[{"cve":"CVE-2026-31431","cvss":7.8,"epss":0.0257,"slug":"cve-2026-31431-linux-kernel-crypto-algif-aead-improper-memory-handling","title":"Linux Kernel crypto algif_aead improper memory handling","severity":"critical","exploited":true,"published_at":"2026-04-22T09:16:21.27+00:00","url":"https://junglewise.ai/threats/cve-2026-31431-linux-kernel-crypto-algif-aead-improper-memory-handling"},{"cve":"CVE-2026-5707","cvss":8.8,"epss":0.0099,"slug":"cve-2026-5707-aws-research-and-engineering-studio-os-command-injection-in","title":"AWS Research and Engineering Studio OS command injection in session name handling","severity":"high","exploited":false,"published_at":"2026-04-06T22:16:25.263+00:00","url":"https://junglewise.ai/threats/cve-2026-5707-aws-research-and-engineering-studio-os-command-injection-in"},{"cve":"CVE-2026-5485","cvss":7.8,"epss":0.0073,"slug":"cve-2026-5485-amazon-athena-odbc-driver-os-command-injection-in-linux","title":"Amazon Athena ODBC driver OS command injection in Linux authentication component","severity":"high","exploited":false,"published_at":"2026-04-03T21:17:12.603+00:00","url":"https://junglewise.ai/threats/cve-2026-5485-amazon-athena-odbc-driver-os-command-injection-in-linux"}],"high":12,"name":"Amazon AWS","rank":17,"slug":"aws","score":52,"vendor":{"name":"Amazon","slug":"amazon"},"critical":1,"max_cvss":8.8,"max_epss":0.0257,"exploited":1,"vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/aws"},{"hub":true,"top":[{"cve":"CVE-2026-31533","cvss":9.8,"epss":0.0026,"slug":"cve-2026-31533-linux-kernel-use-after-free-in-net-tls-encryption-error-path","title":"Linux Kernel use-after-free in net/tls encryption error path","severity":"critical","exploited":false,"published_at":"2026-04-23T18:16:26.857+00:00","url":"https://junglewise.ai/threats/cve-2026-31533-linux-kernel-use-after-free-in-net-tls-encryption-error-path"},{"cve":"CVE-2026-5450","cvss":9.8,"epss":0.0045,"slug":"cve-2026-5450-gnu-glibc-heap-buffer-overflow-in-scanf-mc-specifier","title":"GNU glibc heap buffer overflow in scanf %mc specifier","severity":"critical","exploited":false,"published_at":"2026-04-20T21:16:36.85+00:00","url":"https://junglewise.ai/threats/cve-2026-5450-gnu-glibc-heap-buffer-overflow-in-scanf-mc-specifier"},{"cve":"CVE-2026-31682","cvss":9.1,"epss":0.0042,"slug":"cve-2026-31682-linux-kernel-out-of-bounds-read-in-bridge-br-nd-send","title":"Linux Kernel out-of-bounds read in bridge br_nd_send","severity":"critical","exploited":false,"published_at":"2026-04-25T09:16:01.913+00:00","url":"https://junglewise.ai/threats/cve-2026-31682-linux-kernel-out-of-bounds-read-in-bridge-br-nd-send"}],"high":7,"name":"Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","rank":18,"slug":"siplus-s7-1500-cpu-1518-4-pn-dp-mfp","score":50,"vendor":{"name":"Siemens","slug":"siemens"},"critical":3,"max_cvss":9.8,"max_epss":0.0045,"exploited":0,"vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/siplus-s7-1500-cpu-1518-4-pn-dp-mfp"},{"hub":true,"top":[{"cve":"CVE-2026-20128","cvss":7.5,"epss":0.0009,"slug":"cve-2026-20128-cisco-catalyst-sd-wan-manager-recoverable-password-storage-in-dca","title":"Cisco Catalyst SD-WAN Manager recoverable password storage in DCA","severity":"critical","exploited":true,"published_at":"2026-04-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-20128-cisco-catalyst-sd-wan-manager-recoverable-password-storage-in-dca"},{"cve":"CVE-2026-20133","cvss":7.5,"epss":0.0136,"slug":"cve-2026-20133-cisco-catalyst-sd-wan-manager-information-disclosure","title":"Cisco Catalyst SD-WAN Manager information disclosure","severity":"critical","exploited":true,"published_at":"2026-04-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-20133-cisco-catalyst-sd-wan-manager-information-disclosure"},{"cve":"CVE-2026-20122","cvss":5.4,"epss":0.0174,"slug":"cve-2026-20122-cisco-catalyst-sd-wan-manager-arbitrary-file-overwrite-via-api","title":"Cisco Catalyst SD-WAN Manager arbitrary file overwrite via API","severity":"critical","exploited":true,"published_at":"2026-04-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-20122-cisco-catalyst-sd-wan-manager-arbitrary-file-overwrite-via-api"}],"high":0,"name":"Cisco Catalyst SD-WAN Manager","rank":19,"slug":"catalyst-sd-wan-manager","score":48,"vendor":{"name":"Cisco","slug":"cisco"},"critical":3,"max_cvss":7.5,"max_epss":0.0174,"exploited":3,"vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/catalyst-sd-wan-manager"},{"hub":true,"top":[{"cve":"CVE-2026-40911","cvss":10,"slug":"cve-2026-40911-wwbn-avideo-yptsocket-websocket-broadcast-relay-leads-to","title":"WWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks","severity":"critical","exploited":false,"published_at":"2026-04-14T22:50:05+00:00","url":"https://junglewise.ai/threats/cve-2026-40911-wwbn-avideo-yptsocket-websocket-broadcast-relay-leads-to"},{"cve":"CVE-2026-41304","cvss":9.8,"slug":"cve-2026-41304-wwbn-avideo-rce-cause-by-clonesite-plugin","title":"WWBN AVideo: RCE cause by clonesite plugin","severity":"critical","exploited":false,"published_at":"2026-04-16T21:25:19+00:00","url":"https://junglewise.ai/threats/cve-2026-41304-wwbn-avideo-rce-cause-by-clonesite-plugin"},{"cve":"CVE-2026-41064","cvss":9.3,"slug":"cve-2026-41064-wwbn-avideo-has-an-incomplete-fix-for-command-injection","title":"WWBN AVideo has an incomplete fix for : Command Injection","severity":"critical","exploited":false,"published_at":"2026-04-14T23:27:18+00:00","url":"https://junglewise.ai/threats/cve-2026-41064-wwbn-avideo-has-an-incomplete-fix-for-command-injection"}],"high":7,"name":"Composer Wwbn/Avideo","rank":20,"slug":"wwbn-avideo","score":47,"vendor":{"name":"Composer","slug":"composer"},"critical":3,"max_cvss":10,"max_epss":0.0041,"exploited":0,"vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/wwbn-avideo"},{"hub":true,"top":[{"cve":"CVE-2026-39888","cvss":9.9,"epss":0.0048,"slug":"cve-2026-39888-praisonai-sandbox-escape-via-frame-traversal-in-execute-code","title":"PraisonAI sandbox escape via frame traversal in execute_code","severity":"critical","exploited":false,"published_at":"2026-04-08T21:17:00.99+00:00","url":"https://junglewise.ai/threats/cve-2026-39888-praisonai-sandbox-escape-via-frame-traversal-in-execute-code"},{"cve":"CVE-2026-40288","cvss":9.8,"slug":"cve-2026-40288-mervinpraison-praisonai-rce-via-job-workflow-yaml","title":"MervinPraison PraisonAI RCE via job workflow YAML","severity":"critical","exploited":false,"published_at":"2026-04-10T19:32:48+00:00","url":"https://junglewise.ai/threats/cve-2026-40288-mervinpraison-praisonai-rce-via-job-workflow-yaml"},{"cve":"CVE-2026-40111","cvss":9.8,"slug":"cve-2026-40111-mervinpraison-praisonaiagents-os-command-injection-in-memory","title":"MervinPraison PraisonAIAgents OS command injection in Memory Hooks Executor","severity":"critical","exploited":false,"published_at":"2026-04-10T19:21:54+00:00","url":"https://junglewise.ai/threats/cve-2026-40111-mervinpraison-praisonaiagents-os-command-injection-in-memory"}],"high":6,"name":"MervinPraison PraisonAI Agents","rank":21,"slug":"praisonai-agents","score":45,"vendor":{"name":"MervinPraison","slug":"mervinpraison"},"critical":4,"max_cvss":9.9,"max_epss":0.0052,"exploited":0,"vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/praisonai-agents"},{"hub":true,"top":[{"cve":"CVE-2026-34797","cvss":8.8,"epss":0.0125,"slug":"cve-2026-34797-endian-firewall-os-command-injection-in-logs-smtp-cgi","title":"Endian Firewall OS command injection in logs_smtp.cgi","severity":"high","exploited":false,"published_at":"2026-04-02T15:16:45.3+00:00","url":"https://junglewise.ai/threats/cve-2026-34797-endian-firewall-os-command-injection-in-logs-smtp-cgi"},{"cve":"CVE-2026-34796","cvss":8.8,"epss":0.0147,"slug":"cve-2026-34796-endian-firewall-os-command-injection-in-logs-openvpn-cgi","title":"Endian Firewall OS command injection in logs_openvpn.cgi","severity":"high","exploited":false,"published_at":"2026-04-02T15:16:45.05+00:00","url":"https://junglewise.ai/threats/cve-2026-34796-endian-firewall-os-command-injection-in-logs-openvpn-cgi"},{"cve":"CVE-2026-34795","cvss":8.8,"epss":0.0147,"slug":"cve-2026-34795-endian-firewall-os-command-injection-in-logs-log-cgi","title":"Endian Firewall OS command injection in logs_log.cgi","severity":"high","exploited":false,"published_at":"2026-04-02T15:16:44.8+00:00","url":"https://junglewise.ai/threats/cve-2026-34795-endian-firewall-os-command-injection-in-logs-log-cgi"}],"high":6,"name":"Endian-Firewall-Community","rank":22,"slug":"firewall-community","score":44,"vendor":{"name":"Endian","slug":"endian"},"critical":0,"max_cvss":8.8,"max_epss":0.0147,"exploited":0,"vulnerabilities":32,"url":"https://junglewise.ai/threats/technologies/firewall-community"},{"hub":true,"top":[{"cve":"CVE-2026-6137","cvss":8.8,"slug":"cve-2026-6137-tenda-f451-stack-buffer-overflow-in-fromadvsetwan","title":"Tenda F451 stack buffer overflow in fromAdvSetWan","severity":"high","exploited":false,"published_at":"2026-04-13T00:16:21.3+00:00","url":"https://junglewise.ai/threats/cve-2026-6137-tenda-f451-stack-buffer-overflow-in-fromadvsetwan"},{"cve":"CVE-2026-6136","cvss":8.8,"slug":"cve-2026-6136-tenda-f451-stack-based-buffer-overflow-in-frml7imform","title":"Tenda F451 stack-based buffer overflow in frmL7ImForm","severity":"high","exploited":false,"published_at":"2026-04-13T00:16:21.097+00:00","url":"https://junglewise.ai/threats/cve-2026-6136-tenda-f451-stack-based-buffer-overflow-in-frml7imform"},{"cve":"CVE-2026-6135","cvss":8.8,"slug":"cve-2026-6135-tenda-f451-stack-overflow-in-setipbind","title":"Tenda F451 stack overflow in SetIpBind","severity":"high","exploited":false,"published_at":"2026-04-13T00:16:20.88+00:00","url":"https://junglewise.ai/threats/cve-2026-6135-tenda-f451-stack-overflow-in-setipbind"}],"high":14,"name":"Tenda F451","rank":23,"slug":"f451","score":42,"vendor":{"name":"Tenda","slug":"tenda"},"critical":0,"max_cvss":8.8,"max_epss":null,"exploited":0,"vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/f451"},{"hub":true,"top":[{"cve":"CVE-2026-33824","cvss":9.8,"epss":0.0162,"slug":"cve-2026-33824-microsoft-windows-double-free-in-ike-extension","title":"Microsoft Windows double free in IKE Extension","severity":"critical","exploited":true,"published_at":"2026-04-14T18:17:34.767+00:00","url":"https://junglewise.ai/threats/cve-2026-33824-microsoft-windows-double-free-in-ike-extension"},{"cve":"CVE-2026-32225","cvss":8.8,"epss":0.0091,"slug":"cve-2026-32225-microsoft-windows-shell-protection-mechanism-failure","title":"Microsoft Windows Shell protection mechanism failure","severity":"high","exploited":false,"published_at":"2026-04-14T18:17:30.85+00:00","url":"https://junglewise.ai/threats/cve-2026-32225-microsoft-windows-shell-protection-mechanism-failure"},{"cve":"CVE-2026-33827","cvss":8.1,"epss":0.0084,"slug":"cve-2026-33827-microsoft-windows-tcp-ip-race-condition-remote-code-execution","title":"Microsoft Windows TCP/IP race condition remote code execution","severity":"high","exploited":false,"published_at":"2026-04-14T18:17:35.51+00:00","url":"https://junglewise.ai/threats/cve-2026-33827-microsoft-windows-tcp-ip-race-condition-remote-code-execution"}],"high":8,"name":"Microsoft Windows 10","rank":24,"slug":"windows-10","score":42,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":1,"max_cvss":9.8,"max_epss":0.0345,"exploited":1,"vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/windows-10"},{"hub":true,"top":[{"cve":"CVE-2026-40933","cvss":9.9,"epss":0.0128,"slug":"cve-2026-40933-flowise-flowise-authenticated-rce-in-mcp-adapters","title":"Flowise Flowise authenticated RCE in MCP Adapters","severity":"critical","exploited":false,"published_at":"2026-04-16T21:18:17+00:00","url":"https://junglewise.ai/threats/cve-2026-40933-flowise-flowise-authenticated-rce-in-mcp-adapters"},{"cve":"CVE-2026-41264","cvss":9.8,"epss":0.0117,"slug":"cve-2026-41264-flowise-csv-agent-prompt-injection-remote-code-execution","title":"Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability","severity":"critical","exploited":false,"published_at":"2026-04-21T20:19:52+00:00","url":"https://junglewise.ai/threats/cve-2026-41264-flowise-csv-agent-prompt-injection-remote-code-execution"},{"cve":"CVE-2026-41265","cvss":9.8,"epss":0.0056,"slug":"cve-2026-41265-flowise-airtable-agent-code-injection-remote-code-execution","title":"Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability","severity":"critical","exploited":false,"published_at":"2026-04-18T00:46:04+00:00","url":"https://junglewise.ai/threats/cve-2026-41265-flowise-airtable-agent-code-injection-remote-code-execution"}],"high":7,"name":"Npm Flowise-Components","rank":25,"slug":"flowise-components","score":41,"vendor":{"name":"Npm","slug":"npm"},"critical":3,"max_cvss":9.9,"max_epss":0.0205,"exploited":0,"vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/flowise-components"}],"previous":{"key":"2026-03","top":"Openclaw","period":{"end":"2026-03-31","start":"2026-03-01"},"totals":{"high":442,"critical":147,"exploited":25,"technologies":1075,"vulnerabilities":1652},"url":"https://junglewise.ai/threats/monthly/2026-03"},"next":{"key":"2026-05","top":"Linux Kernel","period":{"end":"2026-05-31","start":"2026-05-01"},"totals":{"high":2075,"critical":517,"exploited":26,"technologies":3603,"vulnerabilities":6351},"url":"https://junglewise.ai/threats/monthly/2026-05"}}